URLhaus Database

You are currently viewing the URLhaus database entry for http://gtech.thngo58.com/zwift-level/xnH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:716848
URL: http://gtech.thngo58.com/zwift-level/xnH/
URL Status:Offline
Host: gtech.thngo58.com
Date added:2020-10-19 09:28:06 UTC
Last online:2020-10-20 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 09:30:15 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:21 hours, 49 minutes Good (down since 2020-10-20 07:19:33 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20MFJ89QRcYvxDRSHZpwOj.exeexe 7284a775fca811ab2470c318347e4cc7c4b0fb53e035c0be746944ad44ac6566Virustotal results 17.14% Heodo
2020-10-20hyfQP8Sg8YgRgWYkbg.exeexe cbafabddb083d9349e88546838eb59deb704e90ea683a08e6f00bb9eac7eff23n/aHeodo
2020-10-20HAQk.exeexe 65329b91f17a9ea0f8e5ce1293b982f7e4c67bbdffe103e3fb3e17498f3a3f85Virustotal results 25.37% Heodo
2020-10-20Y5WHibd.exeexe 06eb695f9336c13d7cab77a4f8eeb3e9913f016c1aee3f6b871a75b00a5a141eVirustotal results 22.54%Heodo
2020-10-20aTRK.exeexe 2d4c49f9b9bf645a32ab186c4f4d8c83d4310b01dd79eca2ad46241f0b5d892an/aHeodo
2020-10-20J7qpIiwnDYg2mxf8S.exeexe 4f2ba087238358f58101df2189d00acc6721c6698dd92f19fa808b9bc5752111n/aHeodo
2020-10-20AgkQKzwQ.exeexe b8ff52a0ba73da23c7adcb872642a3a9a50ca7b7a28a8f2c0f98e9e068e918f1Virustotal results 17.39%Heodo
2020-10-20tyMycF0132MRcccO.exeexe d8083187908fdac811866071de10ab974a8d7d6ce3136a265c767e1f9e11f5aeVirustotal results 17.39% Heodo
2020-10-20JiCTZX1UDnoA.exeexe c691da8e44e5844a6255323addb1e8824ce2b54f699e3ccf30dc8a6b522bedafVirustotal results 17.39%Heodo
2020-10-1946VYQAKR6Tr4F.exeexe 13130339020c4033477ea181b6e57141acb54f625f75c7a56ab49501c4cc4667Virustotal results 16.90% Heodo
2020-10-19H4Jz.exeexe 41fc421d5438f5e1121d8225de805df6bb4fb016095563454c6c8dbfa95324e4Virustotal results 9.86% Heodo
2020-10-19UbqClP4.exeexe 4ced6fa54acdb6a5aadcbf4fa9bd78feb4f43b77a0be67c92e830984da9532f7Virustotal results 7.35% Heodo
2020-10-19e5APV02xLnw4jnqdt6vA.exeexe fb0a20bda9276322716a24134b842653be04e9afeabdb5e758ec469c131ec52an/a Heodo
2020-10-19HdACBDbwNNS5iA3mdppc.exeexe ed282f502be94c6a781a0ae5e4dffa3a2f225fcd7c76d280159bf57f73f0c37dVirustotal results 5.71% Heodo
2020-10-19cywOLeUJ4vnRWETEd7pjS.exeexe d705c8641e5cbfa20258ed54438eca421e0487c70a301223fef7600730f774dbVirustotal results 5.80% Heodo
2020-10-19s9bip2tm54vM.exeexe 671454b8718b590c4aa581f9a0fe3e6cee15a16dd5dc40572a739cd404c4aabbVirustotal results 15.15% Heodo
2020-10-19CPyybJZse3cEV.exeexe e552b65f14daa06fd8019de33aea700e0a625bfa2e5936d784e838b6b2654803Virustotal results 14.08% Heodo
2020-10-191UQyEurH9MxRLB1.exeexe cb29ca0a72bc7e5cfcb8345f5e423ef8a6e2d548035429934f4aecb1f7b91a38Virustotal results 14.29% Heodo
2020-10-19enBwTn.exeexe e38262c0c56ef73f6fafafee7fc2880d6b0e364fb81f36505b7bd0685b197061Virustotal results 12.86% Heodo
2020-10-19yXTlK.exeexe 67a6ef87c30ceb51af70791d3892bd75dea69650ec3076387d3ef339c3725173Virustotal results 12.86% Heodo
2020-10-19K5yAm.exeexe 5372d05b2a76586f65d7b4994763dcb10bfb9297babbcca3f64c4c3bc913304dn/a Heodo